A set of simple tools to help manage staging websites, designed for PHP-powered websites.
When creating or updating a website it's a good idea to publish changes to a staging environment to review before going live.
This package adds the following simple tools to a staging site:
- Secure staging websites behind a simple, accessible login page
- Informs search engine spiders to not index a staging website
It has support for WordPress, Craft CMS, Laravel, Symfony and plain PHP integration.
The staging site login page is a replacement for basic authentication, which doesn't play well with password managers and is blocked by some client systems.
- It detects the current environment and if it matches staging, it displays the staging site login page
- The staging site login page asks for a single password to access the site
- Once the correct password is entered, a cookie is set to remember the login for a set time period (7 days by default)
By default, the login cookie is set to expire after 7 days. The cookie that is used to remember your staging website login also uses your user agent string. If your user agent changes, then you are also logged out.
You can pass the GET parameter ?staging_site_logout=1 to any URL on your staging website to log the user out.
To effectively stop a staging or development website appearing in search engine results we need to:
- Tell search engines to not list web pages in search results
- But allow search engines to access the web pages so they can read this instruction
We can block staging sites from being indexed via the HTTP header X-Robots-Tag:
X-Robots-Tag: "noindex, nofollow"
This package adds this header to all requests on a staging site.
- PHP 8.1+
See the documentation for instructions on how to install this on your website.
You can test the staging login via:
php -S localhost:8000 -t tests/websiteAccess http://localhost:8000 and use the staging password test123
You can run unit tests via:
composer testPlease see CHANGELOG for more information on what has changed recently.
Find out more about how to contribute and our Code of Conduct.
If you discover a security vulnerability within this package, please follow our disclosure procedure.
This package is developed by Studio 24, a human-centered digital agency who build websites and web apps that work for everyone.
The MIT License (MIT). Please see License File for more information.
